fix: replace invalid incomingAuth.oidc with MCPOIDCConfig + oidcConfigRef

The .spec.incomingAuth.oidc inline block is not a valid field in the
v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors.

The correct v0.29.3 API separates OIDC provider config into a dedicated
MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer
via spec.incomingAuth.oidcConfigRef.name.

- Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline
  type, Keycloak issuer, replicated client secrets from keycloak ns)
- Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to
  reference the new MCPOIDCConfig resources via oidcConfigRef
- Register new MCPOIDCConfig files in vmcp-servers kustomization

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
This commit is contained in:
2026-06-15 13:31:45 +00:00
co-authored by Claude Sonnet 4.6
parent d09eb39701
commit 3caeeb2997
5 changed files with 32 additions and 12 deletions
@@ -20,12 +20,8 @@ spec:
name: homelab-embedding
incomingAuth:
type: oidc
oidc:
issuerUrl: https://cloak.olb42.com/realms/home-lab
clientId: toolhive-full-vmcp
clientSecretRef:
name: toolhive-full-vmcp-secret
key: client-secret
oidcConfigRef:
name: full-vmcp-oidc
config:
aggregation:
conflictResolution: prefix